Double free error in Linux kernel - CVE-2017-8890

 

Double free error in Linux kernel - CVE-2017-8890

Published: June 29, 2017 / Updated: June 30, 2017


Vulnerability identifier: #VU7244
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8890
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.

Affected software

Linux kernel
SUSE Linux
Ubuntu
Fedora
kernel

How to mitigate CVE-2017-8890

Install the latest kernel version from vendor's repository.

kernel - addressed in versions 4.10.17-100.fc24, 4.10.17-200.fc25, 4.11.2-300.fc26, 4.11.3-101.fc24, 4.11.3-200.fc25, 4.11.4-100.fc24

External References

Related Security Bulletins